Input validation error in Microsoft SQL Server - CVE-2023-21718

 

Input validation error in Microsoft SQL Server - CVE-2023-21718

Published: February 15, 2023


Vulnerability identifier: #VU72224
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21718
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in Microsoft SQL ODBC Driver. A remote attacker can trick the victim to connect to a malicious SQL server database via ODBC and execute arbitrary code on the system.


Affected software

Microsoft SQL Server
TeleControl Server Basic

How to mitigate CVE-2023-21718

Install updates from vendor's website.

Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6444.4, 2014 SP3 GDR 12.0.6174.8, 2016 SP3 13.0.7024.30, 2016 SP3 GDR 13.0.6430.49, 2017 GDR 14.0.2047.8, 2017 CU31 14.0.3460.9, 2019 GDR 15.0.2101.7, 2019 CU18 15.0.4280.7, 2022 GDR 16.0.1050.5
TeleControl Server Basic - update to 3.1.2

External References

Related Security Bulletins